CVE-2020-9329: Race Condition
Published Feb 21, 2020
·Updated
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
Affected Software
1 affected component
Gogs Gogs<=0.11.91
Remediation
Patch Available
Event History
Feb 21, 2020
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-9329?
CVE-2020-9329 is a vulnerability in Gogs through version 0.11.91 that allows attackers to violate the admin-specified repo-creation policy due to a race condition.
2
What is the severity of CVE-2020-9329?
CVE-2020-9329 has a severity level of medium with a CVSS score of 5.9.
3
How can attackers exploit CVE-2020-9329?
Attackers can exploit CVE-2020-9329 by taking advantage of the internal/db/repo.go race condition in Gogs.
4
How can I fix CVE-2020-9329?
To fix CVE-2020-9329, you should update Gogs to a version beyond 0.11.91.
5
Where can I find more information about CVE-2020-9329?
You can find more information about CVE-2020-9329 on the official GitHub issue page: https://github.com/gogs/gogs/issues/5926